Vulnerability record · CVE-2025-32709 · published 13 May 2025
CVE-2025-32709: Windows Ancillary Function Driver for WinSock privilege escalation flaw
Microsoft · Windows 10 1507
CVE-2025-32709 is a use-after-free (described by NVD as a null pointer dereference) in the Windows Ancillary Function Driver for WinSock (afd.sys) that lets an authorized attacker elevate privileges locally. It affects a broad set of Windows 10, Windows 11 and Windows Server releases. Because it is listed in CISA's Known Exploited Vulnerabilities catalog, it should be treated as actively exploited.
Description
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is a locally exploitable privilege escalation with confirmed exploitation in CISA KEV and high CVSS impact, though it requires an existing low-privileged foothold.
What it is
CVE-2025-32709 is a use-after-free (described by NVD as a null pointer dereference) in the Windows Ancillary Function Driver for WinSock (afd.sys) that lets an authorized attacker elevate privileges locally. It affects a broad set of Windows 10, Windows 11 and Windows Server releases. Because it is listed in CISA's Known Exploited Vulnerabilities catalog, it should be treated as actively exploited.
Impact
A local attacker with existing low-privileged access can gain full control of confidentiality, integrity and availability on the host, effectively escalating to SYSTEM. This enables credential theft, disabling of security controls and lateral movement from the compromised endpoint.
Attack surface
Reached locally through the WinSock ancillary function driver; the CVSS vector (AV:L/PR:L/UI:N) indicates the attacker needs local access and low privileges but no user interaction. No remote or network vector is described.
Exploitation
CISA added it to the KEV catalog on 2025-05-13 with a remediation due date of 2025-06-03, confirming known exploitation; EPSS 30-day probability is 0.0214 (81st percentile). No ransomware campaign use is documented.
What to do
- Apply the Microsoft security update for CVE-2025-32709 on all affected Windows 10, Windows 11 and Windows Server versions as the first action.
- Follow CISA BOD 22-01 guidance and meet the 2025-06-03 remediation deadline; discontinue use of unsupported builds that cannot be patched.
- Restrict and monitor local interactive and service-account access on endpoints to reduce the low-privileged foothold this flaw requires.
- Enable exploit protection and attack surface reduction rules that block common local privilege escalation behavior on Windows hosts.
Detection
- Monitor for unexpected processes gaining SYSTEM integrity from low-privileged parent processes, especially those interacting with afd.sys.
- Hunt for crashes or unusual error events tied to the WinSock ancillary function driver (afd.sys) in Windows event and crash telemetry.
- Correlate local privilege escalation indicators with post-exploitation activity such as credential dumping or security service tampering.
- Track patch state of the affected Windows builds against the Microsoft update guide to find unpatched hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-32709 to the Known Exploited Vulnerabilities catalog on 13 May 2025 as "Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 3 June 2025.
Affected products
15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32709 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32709 | US Government Resource |
Track CVE-2025-32709 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-32709), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.